frm.org
HTML metadata
Technology
- CMS
- Next.js
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (1)
- www.googletagmanager.com×1
Social
Contact
- Phone
- Address
- rue de Varenne, 75007
Registration
- Registrar
- Gandi SAS
- Created
- 1996-12-06
- Expires
- 2026-12-05 199 days left
- Updated
- 2025-07-21
- Name servers
-
- ns-119-c.gandi.net
- ns-152-b.gandi.net
- ns-168-a.gandi.net
DNS records live
- NS
-
- ns-119-c.gandi.net
- ns-152-b.gandi.net
- ns-168-a.gandi.net
- MX
-
- 0 frm-org.mail.protection.outlook.com
- TXT
-
Show 6 TXT records
amazonses:i6xgdq2OS2efRoM4JBPaihRhYARUo6D2aODYauWGVqQ=2lo4t8AaD60WoRTH5APKeV8KZxs=MS=ms59137968brevo-code:985d0736ad3786b9443e8665a30b8c59google-site-verification=KLzi3P__rALSxhC2TPk2Q4W0w4dlhNxN1LMUbVzOM_0google-site-verification=L9RgUDHm4x3Q8fSEe2IQVkU9WwGCsAy0uQcIyDzj34Y
Email authentication strong
- SPF
-
v=spf1 mx ip4:158.255.65.158 ip4:92.243.27.102 ip4:158.255.65.24 ip4:176.31.122.107 ip4:151.80.177.179 include:spf.protection.outlook.com include:spf.sarbacane.com include:alumnforce.org ip4:87.253.232.0/21 ip4:185.189.236.0/22 ip4:185.211.120.0/22 ip4:185.250.236.0/22 ip4:207.253.198.2 ip4:148.59.136.57 include:spf.sendinblue.com include:spf.mandrillapp.com include:spf-eu.letsignit.com include:_spf_quali.netmessage.com -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; pct=100; sp=quarantine;policy: quarantine · sp=quarantine - DKIM
-
Show 4 DKIM selectors
- selector2:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDp7KpJdze7ye1tupW2UpGtvOh7izGqTUDljQMkMcU3I+FrOHiWsmRvy6qWpU87xDYTLb/R/l2kLslmcUEwQj… - mail:
k=rsa;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDeMVIzrCa3T14JsNY0IRv5/2V1/v2itlviLQBwXsa7shBD6TrBkswsFUToPyMRWC9tbR/5ey0nRBH0ZVxp+lsmTxid2Y2z… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA3ZgXwcWene/16Ek/gNrbnVpvYBQcNFIf0UJNiUwOSASiCx5Ildw+gJwK3qYQdVn9eNIbhPQhibbGywFBhp… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDn0gMnId1ksGT/Fj8dWl00J6Q+T9h0P7kKpmM+jdwenCYGmlitz49Qos1w6aecFLCd5ycEXU/0beLgXMYuAv3i61…
selectors probed - selector2:
Certificate (current)
R12
Expires in 58 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin, no-referrer-when-downgrade- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(), ambient-light-sensor=(), autoplay=(), camera=(), cross-origin-isolated=(), display-capture=(), encrypted-media=(), execution-while-not-rendered=(), execution-while-out-of-viewport=(), fullscreen=*, geolocation=(), gyroscope=(), keyboard-map=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=*, publickey-credentials-get=(), screen-wake-lock=*, sync-xhr=(), usb=(), xr-spatial-tracking=(), clipboard-read=(), clipboard-write=(), gamepad=()- x-content-type-options
nosniff- content-security-policy
base-uri 'self'; default-src 'none'; style-src 'unsafe-inline' *; script-src 'unsafe-inline' 'unsafe-eval' *; img-src * data:; media-src 'self'; font-src 'self' fonts.axept.io fonts.gstatic.com adfinitas-statics-cdn.s3.eu-west-3.amazonaws.com fonts.googleapis.com data:; connect-src * data:; worker-src 'none'; frame-src *; form-action 'self'; manifest-src 'self';- strict-transport-security
max-age=31536000; includeSubDomains